Back to skill

Security audit

Kimi Usage Monitor

Security checks for vulnerabilities and agentic risk

Overview

The skill has a coherent Kimi quota-monitoring purpose, but it can read broad authenticated browser tab snapshots and its subagent guard allows spawning when checks fail.

Review before installing. Use this only if you are comfortable giving the skill access to an authenticated Chrome session through OpenClaw, and keep unrelated sensitive tabs out of the attached browser context. Do not rely on the subagent guard as strict enforcement unless the fail-open behavior is changed, and avoid scheduled monitoring until logging, storage, and retention expectations are explicit.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/fetch_usage.py:38
Finding

Overbroad Browser Snapshot Access Violates Least Privilege

Content
View full analysis

Vulnerability Details

File Location: scripts/fetch_usage.py:38-53
Vulnerability Type: Browser access scope violation
Risk Level: Medium

python
# Alternative: look for targetId pattern
import re
matches = re.findall(r'targetId["\']?\s*:\s*["\']?([A-F0-9]+)', tabs_output)

# Try each targetId until we find the Kimi tab
for target_id in matches:
    snap_result = subprocess.run(
        ["openclaw", "browser", "snapshot", "--target-id", target_id],
        capture_output=True,
        text=True,
        timeout=30
    )
    if snap_result.returncode == 0 and "kimi.com" in snap_result.stdout.lower():
        kimi_tab_id = target_id
        snapshot = snap_result.stdout
        break

Technical Analysis

The Skill only needs to read quota information from the Kimi console. However, it extracts every target ID returned by openclaw browser tabs and requests a complete snapshot of each target until snapshot text contains the string kimi.com.

The implementation does not associate a tab's URL with its corresponding target ID before requesting the snapshot. Consequently, unrelated attached tabs may be read before the Kimi tab is found. These tabs can include authenticated email, internal applications, account pages, or other private browser content.

Testing whether snapshot content contains kimi.com is not a reliable origin validation mechanism. An unrelated page can contain that string in visible text, causing it to be misidentified as the Kimi console. The code does not transmit captured snapshots to an external destination, but reading them still exceeds the minimum privileges required by the declared functionality.

Attack Path

  1. The user has multiple browser tabs exposed through the OpenClaw browser integration.
  2. One or more unrelated authenticated or sensitive tabs appear before the actual Kimi console target in the returned target-ID sequence.
  3. The Skill invokes `o ...[truncated 977 chars]
Remediation
View remediation

Remediation Suggestions

  • Parse the browser tab listing as structured data rather than extracting every target ID with a global regular expression.
  • Associate each target ID with its tab URL before requesting any snapshot.
  • Normalize and parse the URL, then require the hostname to be exactly kimi.com or an explicitly approved Kimi subdomain.
  • Require the expected console path, such as /code/console, where practical.
  • Snapshot only the single validated Kimi target.
  • Validate the selected target through trusted browser metadata rather than searching rendered page content for a domain string.
  • Reject malformed, ambiguous, or duplicate tab-list results instead of scanning all tabs.
  • Avoid logging raw snapshots and ensure subprocess buffers containing browser content are discarded promptly.

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/subagent_guard.py:30
Finding

Subagent Quota Guard Fails Open When Usage Inspection Fails

Content
View full analysis

Vulnerability Details

File Location: scripts/subagent_guard.py:30-36
Vulnerability Type: Fail-open authorization logic
Risk Level: Medium

python
if "error" in data:
    print(json.dumps({
        "can_spawn": True,
        "error": data["error"],
        "note": "Defaulting to allow due to check failure"
    }, indent=2))
    sys.exit(0)

Technical Analysis

The subagent guard is intended to prevent expensive subagent operations when remaining Kimi quota is insufficient. When quota inspection fails, however, it returns can_spawn: true and exits with status code 0.

Errors can result from browser unavailability, timeout, malformed subprocess output, JSON parsing failure, a missing Kimi tab, or changes to the console structure. Treating an unknown quota state as approval defeats the guard's primary security and resource-control objective.

Automated callers commonly interpret either can_spawn: true or a zero exit status as authorization. This implementation supplies both signals on failure, making the bypass deterministic whenever quota inspection cannot complete.

Attack Path

  1. A caller invokes scripts/subagent_guard.py before launching a quota-intensive subagent.
  2. The usage check fails because the browser is unavailable, the Kimi tab is absent, the subprocess times out, or its output cannot be parsed.
  3. get_usage() returns an object containing an error field.
  4. The error branch emits "can_spawn": true.
  5. The process exits with status code 0.
  6. The caller interprets the response as approval and starts the subagent even though quota availability is unknown.

A malicious local actor able to disrupt the browser or openclaw command could intentionally trigger this path. It can also occur without an attacker because of ordinary environmental failures.

Impact Assessment

The flaw does not grant operating-system privileges or directly execute attacker-cont ...[truncated 361 chars]

Remediation
View remediation

Remediation Suggestions

  • Fail closed by returning "can_spawn": false and a nonzero exit status whenever quota cannot be verified.
  • Distinguish operational errors from confirmed low-quota decisions in the output schema.
  • Permit degraded operation only through an explicit, documented user override rather than an implicit default.
  • Validate the child process return code before parsing its standard output.
  • Verify that required quota fields are present and within the expected range before authorizing a subagent.
  • Add tests covering browser failure, timeout, malformed JSON, missing usage fields, and unavailable Kimi tabs.
  • Document whether callers should rely on the JSON field, exit status, or both, and keep those signals consistent.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (12)

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The declared purpose is monitoring quota usage, but the skill also describes autonomous allow/deny control over subagent spawning and operational gating based on thresholds. That mismatch is dangerous because users may grant or invoke the skill expecting passive monitoring while it influences execution flow and can change agent behavior in ways not clearly disclosed.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared purpose is monitoring quota usage, but the skill also describes autonomous allow/deny control over subagent spawning and operational gating based on thresholds. That mismatch is dangerous because users may grant or invoke the skill expecting passive monitoring while it influences execution flow and can change agent behavior in ways not clearly disclosed.

Content

No source excerpt is available for this finding.

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · SKILL.md (reported line 115)May include surrounding context.

tensive operation sessions_spawn "Complex research task..." fi

text

## Subagent Guard

Check specifically before spawning subagents:

```bash
python3 scripts/subagent_guard.py

Returns JSON with can_spawn boolean:

json
{
  "can_spawn": true,
  "usage_percent": 45,
  "remaining_percent": 55,
  "resets_hours": 36
}

Integration Ideas

Hourly monitoring cron:

bash
# Add to crontab or OpenClaw jobs
0 * * * * cd /path/to/kimi-usage-monitor && python3 scripts/usage_logger.py

Pre-task validation:

python
import subprocess
result = subprocess.run(
    ["python3", "scripts/preflight_check.py", "intensive"],
    capture_output=True
)
if result.returncode == 0:
    # Proceed with task
    pass

Script Reference

ScriptPurpose
scripts/fetch_usage.pyMain usage scraper (browser-based)
scripts/usage_logger.pyAutonomous logging + decision wrapper
scripts/preflight_check.pyPre-flight validation for operati

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill documents direct shell usage and script execution but does not declare any tool scope such as allowed-tools or permissions. This creates a governance gap: an agent or reviewer cannot easily constrain execution to the minimum required capabilities, increasing the chance of unintended command execution or misuse in broader environments.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The skill promotes autonomous logging of usage patterns and even suggests scheduled hourly collection, but it does not warn users about what data is stored, where it is stored, or how long it is retained. Ongoing background collection can expose account activity patterns or operational metadata without informed consent, especially in shared or managed environments.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/fetch_usage.py (reported line 18)May include surrounding context.

python
"""Get usage data from Kimi console via browser."""
    
    # First, find the Kimi console tab
    result = subprocess.run(
        ["openclaw", "browser", "tabs"],
        capture_output=True,
        text=True,

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest describes a monitoring skill for reading usage and quota information from the Kimi console. Instead of using a direct API or browser library within the process, the code executes external commands to enumerate browser tabs, snapshot pages, and fetch timestamps, which expands the operational capability beyond straightforward usage monitoring.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/fetch_usage.py (reported line 44)May include surrounding context.

python
# Try each targetId until we find the Kimi tab
    for target_id in matches:
        snap_result = subprocess.run(
            ["openclaw", "browser", "snapshot", "--target-id", target_id],
            capture_output=True,
            text=True,

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/fetch_usage.py (reported line 60)May include surrounding context.

python
# Parse usage data from snapshot
    data = {
        "timestamp": subprocess.check_output(["date", "+%Y-%m-%d %H:%M:%S"]).decode().strip()
    }
    
    # Find Weekly usage section

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/preflight_check.py (reported line 17)May include surrounding context.

python
def get_usage():
    """Get current usage."""
    try:
        result = subprocess.run(
            ["python3", str(SKILL_DIR / "scripts/fetch_usage.py"), "--json"],
            capture_output=True,
            text=True,

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/subagent_guard.py (reported line 17)May include surrounding context.

python
def get_usage():
    """Get current usage."""
    try:
        result = subprocess.run(
            ["python3", str(SKILL_DIR / "scripts/fetch_usage.py"), "--json"],
            capture_output=True,
            text=True,

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/usage_logger.py (reported line 20)May include surrounding context.

python
script = SKILL_DIR / "scripts" / "fetch_usage.py"
    
    try:
        result = subprocess.run(
            ["python3", str(script), "--json"],
            capture_output=True,
            text=True,

Static analysis

No suspicious patterns detected.